Babel plugin for resolving Vue types.
42%
Total Score
unhealthy
Risky: its identity resembles the vastly more established resolve package, and the linked repository does not mention this package.
The package resembles the far more established `resolve` package, with 829 million monthly downloads versus 13 million and 93 stable releases versus 11. The README is also identified as referring to the lookalike, making this a severe identity risk for consumers.
The linked repository is `vuejs/babel-plugin-jsx`, does not match the package name, and does not mention this package in its README. Although a subpackage can legitimately live in a monorepo, these values leave package ownership and provenance less transparent.
The repository has no security policy and no reported security-scanning tools. This is a transparency and maintenance-process gap, though it is not evidence that the release is unsafe.
All four workflows were analyzed with no high-confidence audit findings, unsafe untrusted checkouts, or script injections. However, 3 of 4 action references are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@babel/parser Version ^8.0.0 | — | — |
@babel/code-frame Version ^8.0.0 | — | — |
@vue/compiler-sfc Version ^3.5.38 | — | — |
@babel/helper-plugin-utils Version ^8.0.1 | — | — |
@babel/helper-module-imports Version ^8.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.